PoC Index

CVE-2022-39802

HIGH 7.5EPSS 7.1%

SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
7.10% chance of exploitation in the next 30 days, 94th percentile
Published
2022-10-11
Updated
2024-08-03

Proof-of-concept exploits (1)

References

Related